CVE-2026-9998 is an integer overflow vulnerability in Skia affecting Google Chrome versions before 148.0.7778.216. A remote attacker who has already compromised the renderer process may exploit the flaw through a crafted HTML page to escape the browser sandbox. Microsoft Edge is also affected through its Chromium components. The specific vulnerable function is not identified.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python proof-of-concept for CVE-2026-9998, demonstrating insecure deserialization in a simulated blockchain oracle. It contains two code files: vulnerable_oracle.py, which implements a TCP server that listens on port 9999 and base64-decodes then unsafely deserializes incoming data with pickle.loads(); and oracle_exploit.py, which builds a malicious pickle object and sends it to the service. The exploit capability is remote code execution via Python pickle gadget abuse: the RCE class defines __reduce__ to invoke os.popen('id') when deserialized. The repository also includes a README describing the vulnerability and usage, plus a LICENSE file. The vulnerable service is not a real blockchain integration but a simplified oracle/event-listener simulation using socketserver. Overall, the repo’s purpose is to demonstrate how attacker-controlled event/log data processed with pickle can lead to full compromise of the oracle node.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.